Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Bitget $387.5M Hack: How Attackers Moved $185M in One Minute Without Stealing Private Keys

The attackers manipulated Bitget’s backend signing flow to make legitimate security controls approve unauthorized transfers across multiple blockchain networks.

Written By Dishita Malvania
Edited by Divya Mistry
Published 12 hours ago·Updated 2 hours ago
Make The Crypto Times preferred on GoogleGoogle
Hooded hacker typing on a laptop in front of a glowing Bitget exchange logo

Attackers behind the $387.5 million Bitget hack did not steal the exchange’s private keys. They fed forged instructions into Bitget’s own transaction-signing system, which then approved the transfers as if they were legitimate, according to an independent analysis published on September 26 by blockchain security firm GoPlus Security.

The GoPlus review is based on Bitget’s public statements and on-chain timing data, not on an official Bitget postmortem. It places the September 24 incident in the same failure class as the February 2025 Bybit theft. Bitget, one of the largest centralized cryptocurrency exchanges by trading volume, is scheduled to begin restoring withdrawals in phases from today, September 28.

AI Summary
Show
Bitget will resume withdrawals gradually, testing new safeguards to prevent similar signing-chain attacks.
Regulators may tighten oversight on exchange transaction-signing processes after this breach highlights systemic risks.
Investigations could link the hack to North Korean groups, prompting broader geopolitical cybersecurity responses.

What GoPlus Found

“This was not a private-key leak. It was another break in the transaction-signing trust chain,” GoPlus wrote in its September 26 analysis.

A private key is the secret credential that authorizes the movement of funds from a crypto wallet. GoPlus says the attackers never needed it. Instead, they caused Bitget’s own signing system to produce valid signatures for transfers the exchange never intended to send, and those transfers then confirmed on-chain.

The compromise was limited to some of Bitget Exchange’s hot wallets, which stay connected to the internet to process routine withdrawals, and warm wallets, which sit between hot and offline storage. GoPlus says cold storage, the offline reserve, was not affected. Neither was Bitget Wallet, a separately operated self-custody product.

Bitget first put the loss at $351.6 million before revising the figure to $387.5 million. The $35.9 million difference came from Zcash (ZEC) and TRON (TRX) transfers made during the original attack window, not from a second breach. The Crypto Times reported both the initial loss and the revised count on September 25.

The GoPlus reading matches the first-day account from Bitget Chief Executive Officer (CEO) Gracy Chen. In a September 24 security notice, Chen said a critical wallet backend system was compromised, transaction data was spoofed, and the authorization process was triggered. She said the attackers did not forge user withdrawal requests and did not obtain private keys for cold, hot, or warm wallets.

GoPlus frames that as the difference between stealing a key and poisoning the instruction that tells the signer what to approve.

Timeline of the Drain

GoPlus reconstructed the attack as follows. All times are in Coordinated Universal Time (UTC) on September 24.

  • 18:31: An attacker-controlled address was funded with 0.84 ETH to pay network fees, known as gas. The ETH came from a Bitget hot wallet already under the attacker’s control. Bitget says it detected unauthorized transfers in the same minute.
  • 18:58: The first large outflow, about $34.75 million in Tether (USDT), went to the same address funded 27 minutes earlier.
  • 19:00 onward: Stablecoins were swapped for Ether (ETH) on decentralized exchanges (DEXs) and bridged to Ethereum.
  • 19:16: The largest wave moved about $185 million in roughly one minute, including 13,966 ETH on Ethereum, about 91.4 million XRP on the XRP Ledger, and 20.6 million TRX on TRON.
  • 18:58 to 21:23: A multi-chain drain lasting 2 hours and 25 minutes covered ETH, USDT, USD Coin (USDC), Avalanche (AVAX), BNB, Tether Gold (XAUt), XRP, and TRX.
  • About 21:30: Chen posted the security notice, and Bitget paused withdrawals.
  • About 22:00: Roughly $155 million on chains compatible with the Ethereum Virtual Machine (EVM) was split across multiple dormant vault addresses.

XRP made up the largest slice of the stolen assets, a point The Crypto Times covered separately.

GoPlus describes the 0.84 ETH transfer as a dry run. It showed that the attackers could already drive Bitget’s signing path nearly half an hour before the main drain began.

The firm argues the timing matters more than the headline figure. Detection and the first gas funding happened in the same minute, yet the last unauthorized transfer went out at 21:23, almost three hours later. GoPlus says the transfers likely looked legitimate to internal monitoring, or the signing pipeline had no kill switch that could be triggered remotely.

If a circuit breaker had stopped the pipeline after the first $34.75 million USDT transfer, GoPlus estimates that about 90% of the funds would have stayed with the exchange.

Why the Signer Could Not Stop It

GoPlus maps a standard withdrawal path at a centralized exchange in four steps: a user request, backend risk checks, construction of an unsigned transaction, and finally signing and broadcast.

The signing step typically relies on one of three tools. Multi-party computation (MPC) splits control of a key across several parties so no single one holds it in full. A multi-signature (multisig) wallet requires several separate approvals. A hardware security module (HSM) is a tamper-resistant device that stores keys and signs transactions.

According to GoPlus, none of these can judge intent. They sign what the backend hands them. Once attackers poisoned the data that defines what to sign, controls on that same backend, including rules, limits, and approvals, could not veto the action independently. In the firm’s words, the attackers took the risk-decision layer, not the key layer.

GoPlus lists possible entry points only as speculation: database tampering, forged internal calls, message-queue injection, or a swap of the withdrawal-address map. None has been confirmed. Bitget has said it identified and fixed the weakness, but it has not published the entry point. Mandiant, a Google company, and blockchain security firm SlowMist are still investigating.

Same Failure Class as Bybit, Different Surface

GoPlus draws a structural comparison with the February 2025 Bybit theft, which the United States Federal Bureau of Investigation (FBI) put at about $1.5 billion. In that case, attackers tampered with the interface of Safe, a multisig wallet provider, so Bybit’s human signers saw one transaction and approved another.

At Bitget, GoPlus says, there was no human review step to deceive. Automated signing ran on forged backend data.

The firm ties both incidents to the same principle, known as WYSIWYS, or “what you see is what you sign.” Bybit broke on the front end. Bitget broke on the back end.

Both cases are also being linked to hacking clusters associated with the Democratic People’s Republic of Korea (DPRK), commonly known as North Korea. The FBI formally attributed the Bybit theft to North Korea. The Bitget attribution is not settled. Chen has said investigators matched some IP activity to a VPN pattern used by a known DPRK group and that the on-chain pattern resembles earlier operations, describing North Korean involvement as “very likely.” The Crypto Times covered those remarks when she first made them. Bitget has not released the technical evidence behind the assessment.

Attacker Addresses and Tracing

GoPlus says it has blacklisted attacker-linked addresses and shared them with ecosystem partners. First-hop receiving addresses published early in the incident include:

  • 0xA6dD3F218B65E32Ccc37BE30f74884133c655545
  • 0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899
  • 0x600cfeDc6Bd65Fa79B604dC44964f419e45784b2
  • 0x94A43df7687A8494948Be937400e9d5D33135DA0
  • 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
  • 0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C

The number of related addresses has since grown to nearly 900 as the funds were split and moved. Bitget’s stolen-funds tracker remains the exchange’s public map of attacker holdings and transfers. Chen said earlier that some hacker wallets had been frozen.

What It Means for Bitget Users

The GoPlus review does not change the operational picture for customers. Bitget says user balances were not altered, and neither cold storage nor Bitget Wallet has been reported as affected. The exchange says the shortfall is covered by its User Protection Fund, a reserve Bitget maintains to compensate users for losses from security incidents.

Under the plan Bitget posted on September 26, withdrawals return in phases starting September 28, beginning with bitcoin (BTC). The Crypto Times has published the full withdrawal schedule, details of Bitget’s 5% recovery bounty, and an analysis of how the incident compares with FTX.

What the Review Does Not Settle

GoPlus is an independent security firm, not Bitget’s incident responder. Its analysis isolates a control failure that Bitget’s early notices described only in outline, but it is not a root-cause report. It does not identify the attackers’ first foothold, and it does not resolve the question of North Korean involvement.

Two questions remain open. The first is how the attackers entered Bitget’s wallet backend. The second is why a detection logged at 18:31 UTC did not stop transfers that continued until 21:23 UTC. As GoPlus frames it, a signing system that cannot independently flag a first-seen receiving address, a burst across multiple wallets, or a $185 million one-minute outflow is a single point of failure, even when every private key stays secure.

This is a developing story. The Crypto Times will update this report when Bitget publishes a full technical incident report or when independent tracing changes the timeline or the signing-path conclusion.

Also Read: Vietnamese Man Charged Over $16M Crypto Pig Butchering Scam

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Hong Kong Expands Financial Reporting Oversight to Crypto Firms
Hong Kong Expands Financial Reporting Oversight to Crypto Firms
Senate Investigation Finds Widespread Use of Tether’s USDT in Iran-Linked Wallets
Senate Investigation Finds Widespread Use of Tether’s USDT in Iran-Linked Wallets
Chainlink CCIP 2.0 Goes Live With New Institutional Guardrails, LINK Surges
Chainlink CCIP 2.0 Goes Live With New Institutional Guardrails, LINK Surges
Trump's 2 p.m. Oval Office Announcement What It Could Mean for Bitcoin
Trump’s 2 p.m. Oval Office Announcement: What It Could Mean for Bitcoin
The Bybit and Franklin Templeton logos side by side on square plaques against a blue background.
Bybit Adds Franklin Templeton Tokenized Funds as Off-Exchange Collateral

Find Us on Socials

You may also like

Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers

Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days

A hooded figure working on a laptop in front of an illuminated MEXC logo on a dark wall.

MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key

The Citi and Coinbase logos displayed side by side against a blue gradient background.

Citi Expands Coinbase Deal to Let Corporates Accept Stablecoin Payments

India's ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact

India’s ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information